DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // LAZARUS-UNC1069-AXIOSFIRST SEEN: 2009

LAZARUS GROUP (UNC1069 / Sapphire Sleet)

ALSO KNOWN AS: UNC1069, Sapphire Sleet, BlueNoroff, Stardust Chollima, APT38, CryptoCore, TA444, Alluring Pisces, TEMP.Hermit
FROM:DMZ INTELLIGENCE DESK
ORIGIN:North Korea (DPRK — Reconnaissance General Bureau)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:2009
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL95/100
RESOURCES100/100
PERSISTENCE100/100
STEALTH100/100
IMPACT95/100

The BlueNoroff/UNC1069 sub-unit of Lazarus executed the most significant npm supply chain attack of 2026 on March 30-31, poisoning the axios JavaScript package (~100M weekly downloads, present in ~80% of cloud environments) by socially engineering the lead maintainer to steal a long-lived npm access token and publish two malicious versions injecting the WAVESHAPER.V2 RAT (also tracked as SILKBELL by GTIG). The attack was contained in roughly three hours but generated ~600,000 poisoned downloads; OpenAI's macOS app-signing pipeline was exposed, forcing full code-signing certificate rotation. CISA issued an advisory on April 20, 2026, and attribution was confirmed by Microsoft (Sapphire Sleet), Google GTIG (UNC1069), and ThreatBook (Lazarus) independently.

Financial theft to fund DPRK regime; cryptocurrency exchange targeting; supply chain compromise for broad downstream access and credential harvesting

npm maintainer account takeover via social engineering (fake Calendly/Zoom invitations), long-lived npm token theft post-RAT deployment, postinstall lifecycle hook abuse, malicious transitive dependency injection (plain-crypto-js), cross-platform payload delivery (Windows PowerShell, macOS Mach-O NukeSped, Linux Python), WAVESHAPER/SILKBELL RAT, IE8/WinXP user-agent fingerprint (cross-campaign BlueNoroff indicator), AI-generated deepfakes in live video calls, cryptocurrency executive targeting via LinkedIn

SOFTWARE SUPPLY CHAIN
CRYPTOCURRENCY EXCHANGES
FINANCIAL INSTITUTIONS
TECHNOLOGY COMPANIES
AI INFRASTRUCTURE
DEVELOPER ECOSYSTEM

sfrclak[.]com C2 domain; 142.11.206.73 (same /18 netblock as 3 confirmed Lazarus IPs); plain-crypto-js@4.2.1 malicious npm package; attacker-controlled ProtonMail for maintainer account takeover; Quickpacket/Routerhosting/Hostwinds VPS infrastructure (historical BlueNoroff pattern)

FILE DATE: MAR 2026
Operation Axios Poison
Lazarus/UNC1069 socially engineered the axios npm maintainer to publish two backdoored versions (1.14.1 & 0.30.4), deploying WAVESHAPER.V2 RAT across ~600,000 downloads in a 3-hour window; OpenAI's macOS signing pipeline exposed; CISA advisory issued April 20.
FILE DATE: FEB 2026
Crypto Executive Deepfake Campaign
GTIG documented UNC1069 using AI-generated deepfakes and real-time audio impersonation in ████████████████ against cryptocurrency executives, deploying a 7-family malware arsenal including WAVESHAPER, HYPERCALL, and HIDDENCALL.
FILE DATE: JAN 2026
OpenClaw AI Platform Supply Chain Attack
GuidePoint noted the first confirmed large-scale supply chain attack against an agentic AI platform, where a threat actor (attributed to Lazarus umbrella) published 314 malicious 'skills' delivering infostealers to OpenClaw's marketplace.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn